Impact
A difficult-to-exploit weakness in the Composer component of Oracle WebCenter Portal allows an attacker with low privileges but network access via HTTP to gain unauthorized control over critical data. The flaw permits creation, deletion, or modification of portal content, causing integrity breaches, and also enables a partial denial of service that can disrupt access to the portal. The technical weakness is an instance of improper authorization that lets users perform actions beyond their intended level of access.
Affected Systems
Oracle WebCenter Portal version 12.2.1.4.0 and 14.1.2.0.0 within Oracle Fusion Middleware are affected. The vulnerability is scoped to the portal product but may also impact other components that rely on Portal services.
Risk and Exploitability
The CVSS score of 7.7 indicates high severity with significant confidentiality, integrity, and availability impact, and the EPSS score of <1% demonstrates a low exploitation probability. The vulnerability is not listed in the CISA KEV catalog, suggesting no known public exploitation yet. Based on the attack vector, a low‑privileged attacker connected to the network can exploit it via standard HTTP requests, making it a realistic threat if the portal is exposed to untrusted networks.
OpenCVE Enrichment